Bidisha Goswami, Hiten Choudhury
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,050 results · page 20 of 44
Bidisha Goswami, Hiten Choudhury
No abstract is available for this record.
Aisha Zahid Junejo, Manzoor Ahmed Hashmani, Abdullah Alabdulatif, Mehak Maqbool Memon · 6 authors
Preserving anonymity and confidentiality of transactions has become crucial with widespread of the blockchain technology. Despite of the increased efforts for retaining privacy in blockchain networks, invasion attacks are still surfacing. Most of these attacks do not come from outsiders, but from the resident adversarial nodes. Existence of these insider adversaries lead to damaging of an organization’s internal network system and information leakage. Consequently, transaction anonymity and confidentiality are compromised. Hence, adversary detection and filtration play a vital role in protecting networks against unforeseen privacy and security threats. Therefore, in this paper, we propose RZee, a cryptographic and statistical privacy preserving model for adversary detection and filtering in blockchain networks. Firstly, RZee exploits zero-knowledge proofs to cryptographically secure the data. Secondly, based on certain identified conditions, RZee captures node behavior and blacklists malicious nodes to restrict those from injecting harmful data into the chain or viewing transactions as they propagate across the network. This adds an additional layer of protecting transactions from unauthorized and malicious intervention. The proposed framework is evaluated based on various privacy attributes as identified by literature. For this evaluation, 4 different types of experiments have been conducted. Further, the comparison of privacy perseverance of RZee with existing benchmark privacy-preserving frameworks is also done. The results depict that performance and privacy preservation in RZee exceeds the rest with an attribute score of 6.774 and a gain margin of 46.5%.
Mrunal Mhatre, Harshvivek Kashid, Tanisha Jain, Pallavi Vijay Chavan
A key aspect of sustainable business development involves protecting a company’s products from counterfeiting. Since this can impact brand’s image and often, product counterfeits are of a minor quality which can be dangerous and even pose health hazards. Counterfeiters gain profits by manufacturing products using lesser quality materials and production methods. Many counterfeit products in the market are difficult to identify for a normal customer and require to be examined by a trained professional which is time-consuming and costly. In this paper, we propose a method for identifying counterfeit by a simple scan of the quick response code on the product. Since these codes are unique and are implemented by unique algorithms, it is almost impossible to forge them. Also, implementing an encrypted peer-to-peer system for the database makes it impossible for attackers to tamper with the database. The proposed method collectively not only helps laypersons to identify the authenticity of products but also an ownership tracking system where products are linked to the owners’ account which will allow them to produce proof of purchase and authenticity when reselling products and when claiming the warranty of the product. This will help in reducing manufacturing and materials costs used from traditional methods against counterfeiting such as Radio-Frequency Identification and the Hologram technique.
Krishna Prasad Satamraju, Malarkodi Balakrishnan
Integration of healthcare and Internet of Things (IoT) has a potential to revolutionize the medical treatments, diagnosis and predict medical issues thereby enabling patients, families, doctors and medical insurers stay connected for a proactive delivery of services. However, IoT devices operate in infrastructure-less environments, and hence data security and privacy is always a concern. Counterfeit IoT devices create huge menace in sensitive applications. Moreover, conventional healthcare systems are not patient-centric in the sense that they do not include patient’s emotions during treatments. EI helps the clinicians better understand and mange medical procedures. This paper presents a human-centered approach in healthcare domain by the integration of emotional intelligence (EI) and sensor network built around IoT devices. A Raspberry Pi connected with sensors and a camera acts as an IoT device. These sensors collect body vital parameters and Facial expression recognition (FER) based EI. The system is hosted on an Ethereum permissioned blockchain for reliability, security and tamper-proof data sharing and storage. Devices in the network are authenticated using physical unclonable functions (PUFs). Comparative analysis confirms that the PUF-based authentication is 330% faster than conventional methods. The system offers latency of as low as 20 ms. Using smart contracts, the proposed model provides role-based access control and helps in building scalable and harmonious digital healthcare platforms.
Usman Khalil, Owais Ahmed Malik, Mueen Uddin, Chin‐Ling Chen
Smart devices have become an essential part of the architectures such as the Internet of Things (IoT), Cyber-Physical Systems (CPSs), and Internet of Everything (IoE). In contrast, these architectures constitute a system to realize the concept of smart cities and, ultimately, a smart planet. The adoption of these smart devices expands to different cyber-physical systems in smart city architecture, i.e., smart houses, smart healthcare, smart transportation, smart grid, smart agriculture, etc. The edge of the network connects these smart devices (sensors, aggregators, and actuators) that can operate in the physical environment and collects the data, which is further used to make an informed decision through actuation. Here, the security of these devices is immensely important, specifically from an authentication standpoint, as in the case of unauthenticated/malicious assets, the whole infrastructure would be at stake. We provide an updated review of authentication mechanisms by categorizing centralized and distributed architectures. We discuss the security issues regarding the authentication of these IoT-enabled smart devices. We evaluate and analyze the study of the proposed literature schemes that pose authentication challenges in terms of computational costs, communication overheads, and models applied to attain robustness. Hence, lightweight solutions in managing, maintaining, processing, and storing authentication data of IoT-enabled assets are an urgent need. From an integration perspective, cloud computing has provided strong support. In contrast, decentralized ledger technology, i.e., blockchain, light-weight cryptosystems, and Artificial Intelligence (AI)-based solutions, are the areas with much more to explore. Finally, we discuss the future research challenges, which will eventually help address the ambiguities for improvement.
Ming He, Haodi Wang, Yunchuan Sun, Rongfang Bie · 9 authors
Traceability and trustiness are two critical issues in the logistics sector. Blockchain provides a potential way for logistics tracking systems due to its traits of tamper resistance. However, it is non-trivial to apply blockchain on logistics because of firstly, the binding relationship between virtue data and physical location cannot be guaranteed so that frauds may exist. Secondly, it is neither practical to upload complete data on the blockchain due to the limited storage resources nor convincing to trust the digest of the data. This paper proposes a traceable and trustable consortium blockchain for logistics T2L to provide an efficient solution to the mentioned problems. Specifically, the authenticated geocoding data from telecom operators’ base stations are adopted to ensure the location credibility of the data before being uploaded to the blockchain for the purpose of reliable traceability of the logistics. Moreover, we propose a scheme based on Zero Knowledge Proof of Retrievability (ZK BLS-PoR) to ensure the trustiness of the data digest and the proofs to the blockchain. Any user in the system can check the data completeness by verifying the proofs instead of downloading and examining the whole data based on the proposed ZK BLS- PoR scheme, which can provide solid theoretical verification. In all, the proposed T2L framework is a traceable and trustable logistics system with a high level of security.
Manik Gupta, Rakesh Kumar, Shashi Shekhar, Bhisham Sharma · 8 authors
The Internet of Vehicles (IoV) is a new paradigm for vehicular networks. Using diverse access methods, IoV enables vehicles to connect with their surroundings. However, without data security, IoV settings might be hazardous. Because of the IoV's openness and self-organization, they are prone to malevolent attack. To overcome this problem, this paper proposes a revolutionary blockchain-enabled game theory-based authentication mechanism for securing IoVs. Here, a three layer multi-trusted authorization solution is provided in which authentication of vehicles can be performed from initial entry to movement into different trusted authorities' areas without any delay by the use of Physical Unclonable Functions (PUFs) in the beginning and later through duel gaming, and a dynamic Proof-of-Work (dPoW) consensus mechanism. Formal and informal security analyses justify the framework's credibility in more depth with mathematical proofs. A rigorous comparative study demonstrates that the suggested framework achieves greater security and functionality characteristics and provides lower transaction and computation overhead than many of the available solutions so far. However, these solutions never considered the prime concerns of physical cloning and side-channel attacks. However, the framework in this paper is capable of handling them along with all the other security attacks the previous work can handle. Finally, the suggested framework has been subjected to a blockchain implementation to demonstrate its efficacy with duel gaming to achieve authentication in addition to its capability of using lower burdened blockchain at the physical layer, which current blockchain-based authentication models for IoVs do not support.
Ning Xi, Weihui Li, Lv Jing, Jianfeng Ma
Internet of Vehicles (IoV) is a typical application of mobile Internet of Things (IoT), which aims to improve road conditions and enhance the driving experience. However, the issue of identity leakage has drawn a major privacy concern during the vehicle’s authentication. It is impractical to apply traditional anonymous authentication methods directly to the IoV system due to their complex computation. To enhance the user’s privacy and the service’s efficiency, we propose a novel efficient anonymous authentication approach for the IoV based on the zero-knowledge proof (ZKP) and elliptic curve cryptography (ECC). We achieve the user’s strong anonymity and authenticity based on the Fujisaki–Okamoto Commitment algorithm. In addition, the third trusted authority can effectively trace users by tracking users’ verification keys. It holds the user’s traceability when a violation occurs. Meanwhile, we design a fast reconnection procedure based on the security context from the last access, which can reduce the computation overhead effectively. Through the security analysis, it proves that our scheme provides the anonymity, mutual authenticity, unlinkability, traceability, forward security, and replay-attack resistance. The experimental results indicate that our scheme has a better performance compared with the classic protocols in the IoV.
Simge Demir, Şevval Şimşek, Sinem Gür, Albert Lévi
No abstract is available for this record.
Man Chun Chow, Maode Ma
The futuristic fifth-generation cellular network (5G) not only supports high-speed internet, but must also connect a multitude of devices simultaneously without compromising network security. To ensure the security of the network, the Third Generation Partnership Project (3GPP) has standardized the 5G Authentication and Key Agreement (AKA) protocol for mutually authenticating user equipment (UE), base stations, and the core network. However, it has been found that 5G-AKA is vulnerable to many attacks, including linkability attacks, denial-of-service (DoS) attacks, and distributed denial-of-service (DDoS) attacks. To address these security issues and improve the robustness of the 5G network, in this paper, we introduce the Secure Blockchain-based Authentication and Key Agreement for 5G Networks (5GSBA). Using blockchain as a distributed database, our 5GSBA decentralizes authentication functions from a centralized server to all base stations. It can prevent single-point-of-failure and increase the difficulty of DDoS attacks. Moreover, to ensure the data in the blockchain cannot be used for device impersonation, our scheme employs the one-time secret hash function as the device secret key. Furthermore, our 5GSBA can protect device anonymity by mandating the encryption of device identities with Subscription Concealed Identifiers (SUCI). Linkability attacks are also prevented by deprecating the sequence number with Elliptic Curve Diffie-Hellman (ECDH). We use Burrows-Abadi-Needham (BAN) logic and the Scyther tool to formally verify our protocol. The security analysis shows that 5GSBA is superior to 5G-AKA in terms of perfect forward secrecy, device anonymity, and mutual Authentication and Key Agreement (AKA). Additionally, it effectively deters linkability attacks, replay attacks, and most importantly, DoS and DDoS attacks. Finally, the performance evaluation shows that 5GSBA is efficient for both UEs and base stations with reasonably low computational costs and energy consumption.
Xiaoying Jia, Min Luo, Huaqun Wang, Jian Shen · 5 authors
Benefiting from the progress of Internet of Things (IoT) technology, medical devices, wearables, sensors, and users can be connected with each other to form an Internet of Medical Things (IoMT) ecosystem. IoMT improves efficiency, increases accuracy, and reduces the costs of the traditional healthcare system. However, since IoMT involves different entities and heterogeneous networks and carries a large amount of private information, it is a challenging task to ensure data security and protect privacy in the IoMT ecosystem. In this article, we focus on the issue of privacy-aware authentication between entities. We first propose a blockchain-assisted authentication framework for IoMT applications in the fog computing paradigm. Furthermore, we present two privacy-preserving authentication protocols based on elliptic curve cryptography (ECC) and physically unclonable functions (PUFs), respectively, in terms of the capacity of involved entities. Security analysis and performance evaluation demonstrate that compared with several previous protocols, the proposed protocols have competitive computation and communication costs while achieving expected security requirements.
Miaomiao Wang, Lanlan Rui, Yang Yang, Zhipeng Gao · 5 authors
The continuous development of network technology has driven the emergence of smart devices, and the demand for smart devices interconnection has increased sharply, which requires the identity of devices to be authenticated to carry out secure communication. The traditional certificate-based identity authentication scheme can no longer meet the authentication requirements of massive devices. As an authority that issues and manages certificates, Certificate Authority (CA) creates data islands of intra-domain certificates, increasing the complexity of cross-domain authentication. In order to improve the efficiency of cross-domain authentication, this paper introduces blockchain technology, which can establish trust in an untrusted environment. We propose a multi-CA-based authentication architecture to establish distributed trust and share cross-domain certificate information among multiple domains. On this basis, we design a simplified identity authentication scheme to quickly complete cross-domain identity authentication and reduce authentication overhead. To further improve the efficiency of cross-domain authentication, a cross-domain certificate revocation mechanism is designed. The scheme has passed the formal security analysis, and the simulation results show that the cross-domain authentication scheme is efficient.
Shereen Ismail, Diana W. Dawoud, Hassan Reza
Handling nodes identities and authentication is one of the current critical security challenges in an Internet of Things (IoT) environment, which consists of numerous devices with limited computation, communication, storage, and power capabilities. Motivated by the need to maintain trustworthiness in IoT networks to secure node-to-node or user-to-node communication, a blockchain-based identity management and secure authentication mechanism for a Wireless Sensor Network (WSN) scenario is proposed in this paper. The considered WSN is assumed to have three types of nodes: base station, cluster heads, and monitor nodes. The WSN is connected through the base station to the IoT cloud. The proposed system employs a private blockchain for internal authentication of cluster heads and monitor nodes, while a public blockchain is deployed between the base station and the IoT cloud to authenticate communication across different WSNs and end-users. Furthermore, a machine learning-based detection module is utilized to mitigate possible denial-of-service (DoS) attacks that may target cluster head nodes, raising the registration and authentication costs for monitor nodes within its vicinity and amplifying other blockchain attacks.
Mohammed El‐Hajj, Hassan Jradi, Maroun Chamoun, Ahmad Fadlallah
Internet of Things (IoT) has emerged as a key technology with a large spectrum of applications in various fields. However, it still faces several security challenges, in particular authentication-related challenges. Efficient “traditional” authentication solutions are often centralized, which cannot meet all the IoT requirements, especially in term of scalability. This paper proposes a new authentication scheme using the promising distributed ledger technology “IOTA” and the Masked Authenticated Messaging module. The proposed scheme is implemented, simulated and compared to other existing schemes. Its effectiveness is evaluated according to the IoT requirements. The implementation was done In IOTA v1 where IRI played an important role as a coordinator to verify transactions and interact with client library, in the next publication IOTA v2 will be implemented benefiting from Coordicide with the elimination of the coordinator in order to provide a benchmark showing the differences between IOTA v1 and IOTA v2.
Yasser D. Al‐Otaibi
No abstract is available for this record.
Yan Zhang, Bing Li, Jiaxin Wu, Bo Liu · 6 authors
Industrial Internet of Things (IIoT) has emerged as a prospective technology that improves the productivity and automation level for industrial applications. Devices from cooperative IIoT domains will communicate and collaborate on the increasingly complicated manufacturing tasks. To secure cross-domain device collaborations, we propose combining the blockchain with multifactor authentication. Because the multifactor authentication conforms to IIoT devices’ operation modes and brings higher security levels, and the blockchain technology contributes to building trust among different domains. However, this combined usage still has limitations in terms of the potential loss of factor attack, the storage overhead on the blockchain, and the contradiction between efficiency and privacy preservation. Motivated by these facts, in this article, we develop a privacy-preserving blockchain-based multifactor device authentication protocol for cross-domain IIoT. Specifically, multiple factors are additionally encoded by the hardware fingerprint into random numbers, before being transformed into key materials. The blockchain only stores each domain’s dynamic accumulator, which accumulates derived key materials for devices, thereby reducing the overhead. Moreover, the on-chain accumulator is leveraged to efficiently verify the unlinkable identities of cross-domain IIoT devices. The security of our protocol is formally proved, and the security features and functionalities are, respectively, discussed. A proof-of-concept prototype was implemented to prove the efficiency and reliability. The comparison results indicate that the on-chain storage is greatly reduced. Finally, the smart contract’s performance was evaluated to show scalability.
Nelofa Akter, Fahmida Haque, Saha Reno, Mamun Ahmed
In the case of single sign-on (SSO) within the companies, chip-embedded cards can offer highly secured data encryption. For instance, smart cards, a conceptual card with an encoded interconnected chip that serves as a private key, provide personally identifiable information, verification, storing data, and other types of security management. To secure an organization, blockchain technology is adopted since it represents a transparent database. Ethereum is an unauthorized, distributed blockchain system where everyone can manipulate the transaction records. Hyperledger Fabric, on the other hand, is an authorized and secret framework that incorporates the latest calculation of the asset’s properties and the background history of transactions. In classical Smart Card Management System, frequently identified concerns with existing techniques are - physical documents and properties displacement, dispersed blocks containing papers, intermediary and distributors etc. In this paper, we are focused on creating a blockchain-based smart card management system using Hyperledger. Hyperledger has a preprogrammed community of users and application usability for these particular users alone is available so that data is appropriately covered. By accessing the Historical Archive, this system will detect illegal entry and alteration, ensuring information neutrality, security, and authenticity.
Anees Ara, Avinash Sharma, Dharminder Yadav
User authentication is a measurement challenge for handheld devices and online accounts such as bank accounts, social media accounts etc. because illegal access results in money loss and user privacy. Individual devices, online financial services, and intelligent spaces are three significant areas of concern for customer authentication procedures. Three ways have been identified for authentication factors: i) knowledge-factor, ii) Inherence factor, and iii) possession-factor. This study investigates two-way user authentication through image processing. CNN, RCNN, and Deepface are deep learning algorithms used for image recognition. We used imagechain for image storage and Blockchain for personal information storage (mobile number) to secure the database. The database is stored on an Ethereum-based blockchain. After determining whether the image is fake or real, match the webcam image with the imagechain; if both images match, the one-time password is given to the user’s cellphone number for login access. For image processing, Opencv is employed, and the Python library is used to execute machine and deep learning algorithms for user authentication. Test the proposed model on the 10 to 100 users for authentication. Accuracy of this experiment is 75.35, 76.33, 98.18 and cosine similarities of images are much better between images, but in case of fake image identification it achieved 97.35 % accuracy.
Yue Li, Mingcheng Xu, Gaojian Xu
No abstract is available for this record.
Hui Zhang, Weixin Bian, Biao Jie, Shuwan Sun
We propose an efficient identity authentication protocol based on cancelable biometric and Physical Uncloable Function (PUF) namely BioP-TAP, which realizes the two-way authentication between the user and the server. Specially, the concept of biometric template protection is added to the proposed protocol to better protect user privacy. We use the properties of PUF to generate the cancelable biometric and adds it to the authentication protocol. Then, we design a complete authentication protocol combining the elliptic curve Pedersen commitment and Zero-knowledge proof. Finally, we adopt the method of combining formalization and non-formalization to carry out scientific evaluation from multiple perspectives. And the performance analysis and comparison with existing schemes are employed to evaluate the proposed scheme, so as to ensure the effectiveness and security. The results show that the proposed method is more effective for security than existing methods, and more suitable for the user biometric authentication in a multi-server environment.
Jing Zheng, Xiaoliang Wang, Qing Yang, Wenhui Xiao · 6 authors
The Internet of Vehicles is deployed in an open environment, and protecting its security and data privacy is the challenge. Carrying out the Internet of Vehicles secure authentication before interaction of information is an important part of ensuring the security foundation. Therefore, this article designs a safe and reliable Internet of Vehicles authentication and key agreement schemeassisted by blockchain. This article uses a multi-TA network model to improve the efficiency of authentication. Because of the rapid movement of vehicles, it will continue to appear cross-RSU and TA certification. Considering the disadvantages of most centralised authentication protocols using a single TA, this paper uses the multi-TA model to improve the efficiency of authentication. By usingblockchain technology to store the authentication information of vehicles, the cross-domain authentication of vehicles and the protection of user privacy information can be well realised. At the same time, in order to reduce the time of vehicle authentication, this scheme uses a lightweight calculation operation to complete the whole process of authentication. Through security analysis and results of Proverif simulation, the security of the solution is well proved, our scheme can resist various common attacks. Compared with some existing Internet of Vehicles security authentication protocols, the proposed scheme has a lower cost of computation, communication, and storage.
Hariket Sukesh Kumar Sheth, A. K. Ilavarasi, Amit Kumar Tyagi
Because of its ability to make educated judgments, deep learning has gained massive attention in recent years. Many of today's deep learning systems rely on centralized servers and lack operational transparency, traceability, dependability, security, and trustworthy data provenance. Furthermore, using centralized data to train deep learning models exposes them to the single point of failure issue. The relevance of combining blockchain technology and deep learning is highlighted in this study. Deep-learning (DL) techniques are used to authenticate and identify abnormalities and provide security for systems (in cryptographic and biometric systems). Confidentiality and effectiveness must be balanced since network sensors are energy-constrained devices, which is the most crucial idea to consider when establishing a security system that relies on deep-learning techniques and blockchain. Centralized systems have several flaws. Mostly, a network with significant demand for smart devices creates a prodigious amount of data. There is always the possibility that one or more of the centralized network's major components would fail, causing a catastrophic (or full) system failure. The data acquired by the centralized cloud storage frequently necessitates third-party modification. This may result in data breaches, jeopardizing the privacy of the end-user. This paper primarily focuses on the security models proposed in terms of authentication and security using Blockchain, Deep Learning, or the integration of both based on certain characteristics to identify and organize the literature, inclouding type, models, consensus protocols, applications, services, and deployment goals.
Ali Shahidinejad, Dariush Abbasinezhad‐Mood
In vehicular edge computing networks, electric vehicles can get charging services from edge servers through some road-side charging stations. Several recent studies have investigated how to deal with security requirements in these communications. Nevertheless, simultaneous provision of security and lightness, which is crucial for resource-constrained vehicles, is still an open issue. More critically, the anonymity from the perspective of honest-but-curious edge nodes has not been yet addressed. Thus, this paper proposes a novel ultra-lightweight framework for the secure and anonymous communications of vehicles during their charging reception by means of blockchain. Thanks to the blockchain technology, the accountability of electric vehicle possessors guaranteed. The proposed scheme has been validated in terms of security metrics and also implemented on two ARM-based platforms, one 32-bit ARM microcontroller and one 64-bit ARM processor. Further, its blockchain part has been deployed on a Hyperledger Fabric network. The obtained results besides the comparison with well-respected similar schemes acknowledge the usefulness and practicability of the presented scheme.
Keitaro Hashimoto, Shuichi Katsumata, Kris Kwiatkowski, Thomas Prest
No abstract is available for this record.